audit

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided frontend code and design context as its primary data source for auditing. This presents an indirect prompt injection surface. 1. Ingestion points: The skill ingests component source code, page implementations, and design documentation. 2. Boundary markers: No explicit instructions are provided to the agent to treat analyzed code as untrusted or to ignore embedded instructions. 3. Capability inventory: The skill identifies issues and recommends standard development commands (/animate, /polish, etc.) and mentions running CLI-based tools. 4. Sanitization: No sanitization of the input code is specified. Given that this analysis is the primary function of the skill, the risk is negligible.
  • [COMMAND_EXECUTION]: The skill references the use of automated accessibility testing tools including axe-core, WAVE, and Pa11y. These are established, legitimate tools for technical quality assurance and their use here aligns with the skill's stated diagnostic purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 04:03 PM
Security Audit — agent-trust-hub — audit